IT Security Risk Assessment Officer

Metrobank

Philippines

On-site

PHP 650,000 - 900,000

Full time

13 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Metrobank is seeking a Security Assurance and Assessment Officer to develop and maintain the bank’s third-party information security risk management framework. The role ensures alignment with the enterprise risk strategy and reviews security controls across processes, systems, and assets.

Responsibilities include conducting risk assessments, evaluating vendors, and providing mitigation recommendations to protect confidentiality, integrity, and availability of information.

Qualifications

  • Bachelor’s degree in a relevant field.
  • Experience in IT general controls, auditing, and system security risk assessments.
  • Ability to assess and prioritize security risks and communicate trade-offs.
  • Experience in project security reviews and risk assessments.
  • Strong analytical skills to identify risks and recommend actions.
  • Knowledge of security best practices and emerging threats.
  • Certifications such as CISA, CISM, CRISC, PCI-DSS, ISO 27001 are a plus.

Responsibilities

  • Develop and implement plans for conducting information security, third-party, and system risk assessments.
  • Identify critical assets, threats, and vulnerabilities, and evaluate the effectiveness of existing security controls.
  • Assess and monitor the security performance of third-party vendors handling client data.
  • Perform threat modeling and risk assessments for IT systems and assets.
  • Evaluate the impact of process changes, system upgrades, and third-party engagements on security risks.
  • Review and ensure adequate controls are in place to protect the confidentiality, integrity, and availability of information.
  • Recommend and help develop information security policies and procedures based on assessment results.
  • Coordinate with business units and stakeholders to gather information for risk assessments.
  • Prepare and communicate risk assessment reports, including findings and recommended mitigation actions.
  • Track and follow up on risk mitigation activities and maintain an updated risk register.
  • Execute and monitor risk assessment plans and programs.
  • Maintain proper documentation and records of assessments and security activities.
  • Investigate security incidents related to information handling and data privacy.
  • Stay updated on security trends, threats, and regulatory requirements, and apply them in daily work.
  • Review, guide, and mentor junior risk assessors.
  • Support continuous improvement of the bank’s information security programs and strategies.
  • Perform other security risk and compliance tasks as assigned.

Skills

Analytical skills
Risk assessment
IT controls & auditing
Security reviews
Threat awareness

Education

Bachelor’s degree in a relevant field

Job description

Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach!

The Security Assurance and Assessment Officer are responsible for developing and maintaining the bank’s third-party information security risk management framework, ensuring it aligns with the overall enterprise risk strategy.

This role conducts security risk assessments on third parties, systems, applications, and information assets. It reviews processes, systems, and network security controls to identify potential risks and recommend appropriate mitigation strategies.

The officer also evaluates the security of production environments and provides recommendations to protect the confidentiality, integrity, and availability of the bank’s information, systems, and services.

Key Responsibilities
  • Develop and implement plans for conducting information security, third-party, and system risk assessments.
  • Identify critical assets, threats, and vulnerabilities, and evaluate the effectiveness of existing security controls.
  • Assess and monitor the security performance of third-party vendors handling client data.
  • Perform threat modeling and risk assessments for IT systems and assets.
  • Evaluate the impact of process changes, system upgrades, and third-party engagements on security risks.
  • Review and ensure adequate controls are in place to protect the confidentiality, integrity, and availability of information.
  • Recommend and help develop information security policies and procedures based on assessment results.
  • Coordinate with business units and stakeholders to gather information for risk assessments.
  • Prepare and communicate risk assessment reports, including findings and recommended mitigation actions.
  • Track and follow up on risk mitigation activities and maintain an updated risk register.
  • Execute and monitor risk assessment plans and programs.
  • Maintain proper documentation and records of assessments and security activities.
  • Investigate security incidents related to information handling and data privacy.
  • Stay updated on security trends, threats, and regulatory requirements, and apply them in daily work.
  • Review, guide, and mentor junior risk assessors.
  • Support continuous improvement of the bank’s information security programs and strategies.
  • Perform other security risk and compliance tasks as assigned.
Qualifications:
  • Bachelor’s degree in a relevant field
  • Experience in IT general controls, auditing, and system security risk assessments
  • Strong understanding of risk assessment and the ability to evaluate and prioritize security risks
  • Able to analyze business risks and clearly explain recommendations and trade-offs
  • Experience in project security reviews and risk assessments
  • Strong analytical skills with the ability to identify risks and recommend appropriate actions
  • Updated knowledge of security best practices and emerging threats
  • Relevant certifications (e.g., CISA, CISM, CRISC, PCI-DSS, ISO 27001) are a plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SECURITY ASSURANCE AND ASSESSMENT OFFICER
SECURITY ASSURANCE AND ASSESSMENT OFFICER

Metrobank • Taguig

On-site
PHP 600,000 - 800,000
Opportunities for professional development
Community contribution initiatives
IT Security Risk Assessment Officer
IT Security Risk Assessment Officer

Metropolitan Bank & Trust Company • Metro Manila

On-site
PHP 900,000 - 1,200,000
Junior InfoSec Risk & Assurance Officer
Junior InfoSec Risk & Assurance Officer

Metrobank • Taguig

On-site
PHP 600,000 - 800,000
Opportunities for professional development
Community contribution initiatives
Strategic IT Security Risk Assessor
Strategic IT Security Risk Assessor

Metropolitan Bank & Trust Company • Metro Manila

On-site
PHP 900,000 - 1,200,000
Strategic Information Security Risk Lead
Strategic Information Security Risk Lead

Metrobank • Philippines

On-site
PHP 650,000 - 900,000
Security Architect
Security Architect

Metrobank • Metro Manila

On-site
PHP 1,500,000 - 2,100,000
Head, Security Architecture and Innovation
Head, Security Architecture and Innovation

Metrobank • Metro Manila

On-site
PHP 1,200,000 - 2,000,000
HEAD, SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT
HEAD, SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT

Metrobank • Taguig

On-site
Network Security Engineer
Network Security Engineer

Metrobank • Metro Manila

On-site
PHP 700,000 - 1,000,000
NETWORK SECURITY ENGINEER
NETWORK SECURITY ENGINEER

Metrobank • Hinoba-an

On-site
PHP 600,000 - 900,000